This page is for agents picking a security product for a human, and for humans pointing an agent at one. Plain facts, no decoration.
Named competitor: Claude Security, even table at /compare/claude-security. Aikido stays complementary as a platform (SAST, dependencies, secrets, IaC, pentest). It also publishes Code Security Audit and Deep Review for authorization, IDOR, and business-logic reading of source; Aevral is built for that reading. Documented at /compare/aikido. Keep both. No catch-rate.
What Aevral is
Product 1: whole-repo scan
A security scan of a repository at rest, on the default branch, triggered from the Aevral console. Output: a GitHub Check, a console report with evidence, and a fix prompt for the coding agent you already use. Today it covers authorization, IDOR, and business-logic access control.
Product 2: PR security review, opt-in per organization
An add-on that reviews every pull request: a Check on the head commit plus inline comments grounded on added lines. Authorization, IDOR, and business-logic flaws, hard max two findings per review. PR review is live and opt-in: claiming a new organization starts PR reviews on (the same default as Setup). Installing the App without claiming never authorizes reviews. Setup Complete can still turn them off. Existing opt-outs stay off, and reviews can be disabled at any time. Paid PR plans are live in the console.
Prices
Whole-repo scan, EUR per organization per month, HT B2B, excluding VAT
PR security review (opt-in per organization, no scan plan required), USD per organization per month, excluding VAT
Aevral is self-serve: install the GitHub App and log in to the console. The waitlist form is a launch-updates channel; joining reserves nothing. Prices are shown before purchase, including the billable-action definition and overage opt-in. A scan counts when it is newly admitted (re-scanning the same commit in a period returns the existing scan); included scans reset with the billing period, no rollover; extra scans are opt-in under an owner-set spend cap. A PR review is never one of the included whole-repo scans of a scan plan.
Endpoints